Full Account Takeover on Dropbox.

Disclosed by
R3dpars3c
  • Engagement Dropbox
  • Disclosed date 10 months ago
  • Points 20
  • Priority P2 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Dropbox

This report demonstrated a type of phishing attack that could lead to an account takeover. A fix for the issue has been released and it was applied for existing users through an automatic update.

Summary by R3dpars3c

Please disclose everything of this report.

Activity